An enterprise organization is migrating its core billing application to a public cloud using an Infrastructure as a Service (IaaS) deployment model. Which of the following security tasks remain the direct responsibility of the enterprise customer within this framework? (Select TWO.)
- Hardening guest operating systems and configuring host-level firewallsAnswer
- Configuring identity access controls and defining resource authorization policiesAnswer
- CApplying firmware updates to physical server blades and hypervisors
- DAssuming identity authentication automatically satisfies resource authorization without configuring access rules
Answer
The customer is responsible for hardening guest operating systems and host-level firewalls, as well as configuring identity access controls and resource authorization policies.
Under the cloud shared responsibility model for Infrastructure as a Service (IaaS), the cloud provider manages the physical datacenters, server hardware, and virtualization hypervisors. The customer retains full ownership and operational responsibility for guest operating systems, software patching, host-based security controls, and user access authorization.
Step-by-Step Solution
Key Concept
Cloud Shared Responsibility Model (IaaS)